Privacy Policy

Last updated: May 21, 2026

1. Introduction

Welcome to Traceipt (“we,” “our,” or “us”). Traceipt is a receipt scanning and budget tracking application available at traceipt.com. We help you digitize receipts, track spending by category, and stay on top of your monthly budgets with smart email alerts.

This Privacy Policy explains what information we collect, how we use it, and what rights you have regarding your data. By using Traceipt, you agree to the practices described in this policy.

2. Information We Collect

We collect the following categories of information:

  • Account information: Your email address and name when you sign up or authenticate via Google OAuth.
  • Receipt images and data: Photos of receipts you upload, along with the extracted data (store name, date, line items, totals, and categories) processed by our AI.
  • Payment information: Billing details are handled entirely by Stripe. We do not store your credit card numbers on our servers.
  • Budget data: Category budget limits you set and your spending history over time.
  • Usage data: Log data including IP addresses, browser type, pages visited, and actions taken within the app to help us diagnose issues and improve the service.

3. How We Use Your Information

We use the information we collect to:

  • Scan and extract structured data from your receipt images using AI.
  • Send email copies of your scanned receipts to your registered email address.
  • Track your spending against the budget limits you set.
  • Send budget alert emails — a warning when you reach 80% of a budget and a notification when you exceed 100%.
  • Process subscription payments and manage your billing via Stripe.
  • Authenticate your identity and keep your account secure.
  • Improve and troubleshoot the service using aggregated usage analytics.

4. How We Store Your Data

Your data is stored in Supabase, a secure cloud database platform with encryption at rest and in transit. Supabase uses row-level security (RLS) to ensure that each user can only access their own data — even at the database level, your records are isolated from other users.

Receipt images are stored in Supabase Storage, a secure object storage service. Image files are accessible only through authenticated, signed URLs that expire after a short period.

We retain your data for as long as your account is active. If you delete your account, your data is permanently removed within 30 days.

5. Third-Party Services

Traceipt relies on the following third-party services to operate. Each has its own privacy policy governing how they handle data:

  • Anthropic Claude API — powers our AI receipt scanning. Receipt image data is sent to Anthropic for processing. Anthropic does not retain your data for training purposes under their API terms.
  • Supabase — database storage, authentication, and file storage.
  • Stripe — payment processing and subscription management. We never see or store your full card details.
  • Resend — transactional email delivery for receipt copies and budget alerts.
  • Vercel — application hosting and edge infrastructure.

6. Email Communications

By creating an account, you agree to receive the following transactional emails:

  • Receipt copies: A formatted email with the extracted receipt data every time you scan a receipt.
  • Budget warnings: A notification when your spending reaches 80% of a category budget (at most once per day per category).
  • Budget exceeded alerts: A notification when your spending exceeds 100% of a category budget (at most once per day per category).

These are service emails essential to the Traceipt product. We do not send promotional or marketing emails without your explicit consent.

7. Data Sharing

We never sell, rent, or trade your personal data to third parties. We only share data with the service providers listed in Section 5 — and only to the extent necessary for them to provide their services to us on your behalf.

We may disclose your information if required by law, court order, or to protect the rights and safety of Traceipt, our users, or the public.

8. Your Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of all personal data we hold about you.
  • Correction: Request that we correct inaccurate or incomplete data.
  • Deletion: Request permanent deletion of your account and all associated data.
  • Portability: Request an export of your receipt data in a machine-readable format.
  • Objection: Object to certain processing of your personal data.

To exercise any of these rights, email us at privacy@traceipt.com. We will respond within 30 days.

9. Children's Privacy

Traceipt is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected data from a child, please contact us immediately at privacy@traceipt.com and we will delete it promptly.

10. Security

We take the security of your data seriously and implement industry-standard safeguards:

  • SSL/TLS encryption for all data in transit between your browser and our servers.
  • Encryption at rest for all data stored in Supabase.
  • Row-level security (RLS) in our database, enforcing that users can only query their own records.
  • Signed, time-limited URLs for access to stored receipt images.

No system is completely secure. In the unlikely event of a data breach, we will notify affected users within 72 hours where required by law.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us: